Microsoft Releases May 2022 Security Updates
Scheduled updates for Microsoft products
Summary
Scheduled updates for Microsoft products
Affected platforms
The following platforms are known to be affected:
The following platforms are also known to be affected:
Other products included
- Windows Active Directory
- Microsoft Graphics Component
- Microsoft Local Security Authority Server (lsasrv)
- Microsoft Office Excel
- Microsoft Windows ALPC
- Role: Windows Fax Service
- Role: Windows Hyper-V
- Self-hosted Integration Runtime
- Tablet Windows User Interface
- Visual Studio Code
- Windows Active Directory
- Windows Address Book
- Windows Authentication Methods
- Windows BitLocker
- Windows Cluster Shared Volume (CSV)
- Windows Failover Cluster Automation Server
- Windows Kerberos
- Windows Kernel
- Windows LDAP - Lightweight Directory Access Protocol
- Windows Media
- Windows Network File System
- Windows NTFS
- Windows Point-to-Point Tunneling Protocol
- Windows Print Spooler Components
- Windows Push Notifications
- Windows Remote Access Connection Manager
- Windows Remote Desktop
- Windows Remote Procedure Call Runtime
- Windows Server Service
- Windows Storage Spaces Controller
- Windows WLAN Auto Config Service
Threat details
Introduction
Microsoft has released updates to address 75 vulnerabilities in Microsoft software, with 8 vulnerabilities considered critical. An unauthenticated remote attacker can exploit some of these vulnerabilities to take control of an affected system.
Exploitation of CVE-2022-26925 in the wild
On 1 July 2022, CISA added CVE-2022-26925, a 'Windows Local Security Authority (LSA) Spoofing Vulnerability', to their Known Exploited Vulnerabilities Catalog. This catalogue is used to describe vulnerabilities that are frequent attack vectors for malicious cyber actors and therefore pose a significant risk.
The vulnerability was addressed in the out-of-band (OOB) updates to Microsoft's May 2022 Security Update (see the Threat Updates section below).
CVE-2022-26925 could be exploited as part of a New Technology LAN Manager (NTLM) Relay Attack, which enables an attacker-controlled device to assume the identity and privileges of a targeted device. If a domain controller is targeted, this could result in a full domain compromise.
Further details of this vulnerability, including advice for protecting against NTLM Relay Attacks, can be found on Microsoft's Security Update Guide for CVE-2022-26925.
Threat updates
| Date | Update |
|---|---|
| 20 May 2022 |
Microsoft releases out-of-band update to address authentication failure issues after installing the May Windows update
Microsoft have released out-of-band (OOB) updates for Domain Controllers in response to the authentication failures observed after applying the May 2022 monthly security updates. These failures were related to how the mapping of certificates to machine accounts was being handled by the domain controller. Affected organisations are encouraged to review the relevant advisories below. Cumulative updates
Standalone Updates:
|
Remediation advice
Affected organisations are encouraged to review Microsoft’s May 2022 Security Update Summary and Deployment Information and apply the necessary updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 4 July 2022 1:27 pm